Palo Alto Networks Certified Network Security Architect Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 250 questions. Use the simulator for timed and flashcard mode.

Try Simulator

NetSec-Architect Sample Questions

  1. Question 1

    Q1

    A financial institution requires strict Zero Trust implementation for their internal network. They need to ensure that access to the 'Core-Banking' zone is restricted not just by user identity, but also by the specific device being used, ensuring no unmanaged devices can connect. The solution must persist even if the device IP changes. Which combination of Palo Alto Networks features should the architect design into the security policy?

    Show answer & explanation

    Correct answer: B

    Device-ID provides persistent identification of a device regardless of network changes (like IP address) and allows policy enforcement based on the specific device itself, not just the user or IP. Combining User-ID (who) with Device-ID (which machine) creates the required precise Zero Trust policy control.

  2. Question 2

    Q2

    An architect is designing a network segmentation strategy for a manufacturing plant. The requirement is to isolate legacy OT systems from the IT network while allowing specific SCADA protocols. The customer is confused about the difference between Network Segmentation and Microsegmentation. Which statement accurately differentiates these concepts in this context?

    Show answer & explanation

    Correct answer: A

    Network segmentation is a broad isolation strategy (North-South or Zone-based), typically using VLANs. Microsegmentation is granular (East-West), isolating individual workloads (like a specific server or container) regardless of their network location, essential for Zero Trust.

  3. Question 3

    Q3

    A retail chain is deploying Prisma Access to secure their remote branches. They need to ensure that all web traffic, including SSL/TLS encrypted traffic, is inspected for zero-day malware without significantly impacting user experience. Which configuration ensures continuous security scanning of this allowed traffic?

    Show answer & explanation

    Correct answer: A

    To scan for malware inside encrypted traffic, SSL Decryption (Forward Proxy) is mandatory to expose the payload. WildFire is the specific service for detecting zero-day and unknown malware. Both must be combined.

  4. Question 4

    Q4

    Which service is essential for implementing continuous monitoring and analytics in a Zero Trust environment to detect anomalous behavior and visualize trust levels across the entire estate?

    Show answer & explanation

    Correct answer: A

    Strata Logging Service (formerly Cortex Data Lake) creates the centralized data repository required for analytics, AI/ML processing, and unified visibility, which are prerequisites for continuous monitoring in a Zero Trust architecture.

  5. Question 5

    Q5

    A healthcare organization is developing an internal Generative AI application. They need to ensure that the AI model itself is not manipulated (prompt injection) and that sensitive patient data is not inadvertently included in the model training or output. Which Palo Alto Networks solution specifically addresses the runtime security of the AI model and its interactions?

    Show answer & explanation

    Correct answer: A

    Prisma AIRS is specifically designed to secure the AI ecosystem, including model scanning, AI Red Teaming, and runtime protection against threats like prompt injection and data leakage within the AI pipeline.

  6. Question 6

    Q6

    An architect is deploying Prisma AIRS to secure a Kubernetes-based AI inference cluster. The requirement is to enforce microsegmentation between the 'Ingest', 'Inference', and 'Output' pods. Which component enables this visibility and control within the Kubernetes environment?

    Show answer & explanation

    Correct answer: A

    In a Kubernetes environment, Prisma AIRS (leveraging Prisma Cloud technology) deploys as a DaemonSet (Defender) on each node to provide deep visibility and enforce microsegmentation policies at the pod/container level.

  7. Question 7

    Q7

    When designing access controls for employees using public Generative AI tools (like ChatGPT or Gemini), which feature of 'AI Access' allows the organization to distinguish between enterprise and consumer versions of the same application to enforce data controls?

    Show answer & explanation

    Correct answer: A

    The App-ID Cloud Engine (ACE) provides advanced application identification capabilities that can distinguish between different functional aspects and versions of SaaS applications, such as distinguishing 'ChatGPT Enterprise' from 'ChatGPT Consumer'.

  8. Question 8

    Q8Multiple answers

    Select TWO key functions of Prisma AIRS 'AI Red Teaming' capabilities. (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    AI Red Teaming involves simulating attacks to find vulnerabilities like jailbreaks or prompt injections before deployment.

    Red Teaming also includes assessing the security posture of the model's components and supply chain risks.

  9. Question 9

    Q9

    Which architectural component is primarily responsible for ensuring that AI applications comply with GDPR data residency requirements by preventing sensitive PII from being sent to AI models hosted in non-compliant regions?

    Show answer & explanation

    Correct answer: A

    Enterprise DLP can identify sensitive data (PII) and enforce policies based on destination, ensuring data does not cross borders into non-compliant regions/applications.

  10. Question 10

    Q10

    You are advising a customer on securing their new internal AI chatbot. They need to prevent employees from pasting proprietary source code into the chat interface. Which specific DLP classifier method would be most effective and accurate for this use case?

    Show answer & explanation

    Correct answer: A

    ML classifiers are best suited for detecting source code and unstructured proprietary data patterns that are difficult to capture with simple regex or keywords.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the NetSec-Architect sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 250 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon